{"id":58,"date":"2008-12-31T14:16:29","date_gmt":"2008-12-31T18:16:29","guid":{"rendered":"http:\/\/puck.nether.net\/~jared\/blog\/?p=58"},"modified":"2008-12-31T14:16:29","modified_gmt":"2008-12-31T18:16:29","slug":"good-malware","status":"publish","type":"post","link":"https:\/\/puck.nether.net\/~jared\/blog\/?p=58","title":{"rendered":"Good malware?"},"content":{"rendered":"<p>I&#8217;ve always thought about the idea of &#8220;Good&#8221; malware as a solution to some of the problems out there.  The idea being that you use the same techniques used to compromise systems but to change some settings to a more secure value, but using some of the subversive methods to propogate.<\/p>\n<p>Some of the settings that I consider a good default to change:<br \/>\n* Daily checks for software updates + Auto-Install of these updates<br \/>\n* Disable compromising features (eg: AutoRun)<\/p>\n<p>Things to perhaps change<br \/>\n* Disable ActiveX<br \/>\n* Enable firewall (w\/ exception handling)<br \/>\n* Nuke all AutoRun items<br \/>\n* Nuke all MSIE malware\/extensions except &#8220;safe&#8221; plugins, eg: flash, quicktime, silverlight, etc..<\/p>\n<p>The natural problem with this is doing good things with these bad techniques would likely get you classified as a virus\/malware, and certainly if you attempt to do some of the network-scanning activities to distribute yourself.  Too bad one cannot justify such activities legally.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve always thought about the idea of &#8220;Good&#8221; malware as a solution to some of the problems out there. The idea being that you use the same techniques used to compromise systems but to change some settings to a more secure value, but using some of the subversive methods to propogate. Some of the settings [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-58","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=\/wp\/v2\/posts\/58","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=58"}],"version-history":[{"count":0,"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=\/wp\/v2\/posts\/58\/revisions"}],"wp:attachment":[{"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=58"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=58"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/puck.nether.net\/~jared\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=58"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}